meitu-beauty

Pass

Audited by Gen Agent Trust Hub on Apr 7, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The skill invokes the vendor-provided meitu-cli tool to perform image beauty enhancement and environment verification. It also executes a local Node.js script (oc-workspace.mjs) to determine workspace configurations and output paths. These actions are limited to the skill's intended image processing functionality.
  • [EXTERNAL_DOWNLOADS]: The skill documentation guides the user to install the meitu-cli package via the npm registry. As a vendor-owned resource, this is considered a standard dependency for the skill's operation.
  • [DATA_EXFILTRATION]: Portrait images provided by the user (as local files or via URLs) are transmitted to the Meitu API through the CLI tool for processing. This data movement is essential for the core functionality of the AI beauty service and is explicitly documented.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 7, 2026, 11:58 PM